CVE-2026-14975 | JoomUnited WP File Download Plugin up to 6.3.8 on WordPress Streaming Endpoint file.save remoteurl path traversal

SecurityVulns

A vulnerability described as problematic has been identified in JoomUnited WP File Download Plugin up to 6.3.8 on WordPress. Impacted is the function file.save of the component Streaming Endpoint. Executing a manipulation of the argument remoteurl can lead to path traversal.

This vulnerability is registered as CVE-2026-14975. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More